First published: Fri Dec 19 2014(Updated: )
Cross-site scripting (XSS) vulnerability in nds/search/data in iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allows remote attackers to inject arbitrary web script or HTML via the rdn parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus NetIQ eDirectory | <=8.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5212 is considered a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2014-5212, update to Novell eDirectory version 8.8 SP8 Patch 4 or later.
CVE-2014-5212 affects the iMonitor feature in Novell eDirectory versions before 8.8 SP8 Patch 4.
The impact of CVE-2014-5212 allows remote attackers to inject arbitrary web script or HTML which may lead to data theft or session hijacking.
CVE-2014-5212 is not limited to specific browsers and affects any client that interacts with the vulnerable iMonitor interface.